A likely Russian-speaking threat actor used hundreds of AI agents to build and launch a fast-moving global campaign against vulnerable PaperCut NG/MF servers, exploiting CVE-2026-81578 and CVE-2026-82078. GreyNoise says the operation compromised hundreds of organizations worldwide and used post-exploitation techniques to harvest credentials and gain domain-level access, underscoring how AI can compress attack timelines dramatically. #PaperCut #CVE-2026-81578 #CVE-2026-82078 #GreyNoise #Codex #DeepSeek #Netlas
Keypoints
- AI agents were used to develop and refine exploits for PaperCut NG/MF flaws.
- The campaign began on August 31 and combined Codex, DeepSeek, and commodity offensive tools.
- At least 440 PaperCut instances across 395 organizations in 48 countries were compromised.
- Attackers harvested credentials, domain secrets, and administrator access from multiple victims.
- The operation used LSASS dumping, noPac, and DCSync to expand access inside networks.